Home Malware Programs Rogue Anti-Virus Programs AV Defender

AV Defender

Posted: July 5, 2010

AV Defender is a rogue anti-virus program that reports false threats and displays fake security alerts on your PC. AV Defender does this to convince you that your computer is infected with malware. This fake program is promoted and installed through the use of Trojans and often comes bundled with other malicious software. AVDefender is part of a blatant scam used to con you into paying for removal of infections which don't exist. Remove AV Defender and all associated threats using an updated anti-virus program.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %UserProfile%\Desktop\AV Defender.lnk
    2 %UserProfile%\Start Menu\Programs\AV Defender
    3 %UserProfile%\Start Menu\Programs\AV Defender\AV Defender.lnk
    4 c:\Documents and Settings\All Users\Microsoft PData
    5 c:\Documents and Settings\All Users\Microsoft PData\track.wid
    6 c:\Program Files\AV Defender
    7 c:\Program Files\AV Defender\advanceddefender.exe
    8 c:\Program Files\AV Defender\base.wdb
    9 c:\Program Files\AV Defender\baseadd.wdb
    10 c:\Program Files\AV Defender\conf.wcf
    11 c:\Program Files\AV Defender\q
    12 c:\Program Files\AV Defender\quarant.wdb
    13 c:\WINDOWS\certofsystem.exe
    14 c:\WINDOWS\explorers.exe
    15 c:\WINDOWS\microsoftdefend.dll
    16 c:\WINDOWS\regp.exe
    17 c:\WINDOWS\secureit.com
    18 c:\WINDOWS\spoos.exe
    19 c:\WINDOWS\system32\winscent.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = "1"HKEY_LOCAL_MACHINE\SOFTWARE\AV DefenderHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "avdefender"HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}AV Defender

Related Posts

Loading...